File Provenance via App Container Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems lack the ability to authentically report the provenance of files, leading to suboptimal user experiences and security challenges when desktop applications and modern apps interact, as they cannot mutually trust each other due to limitations in existing trust mechanisms like Mark of the Web (MotW), which cannot differentiate security treatments based on the apps that created files.

Innovation Solution

Enhancing file metadata to record the identification and opinion of the app that wrote a file, using the Mark of the App Container (MotAC) technology, which allows the operating system to mark files with the identifier of the app container, enabling apps to make informed security decisions based on the provenance and trustworthiness of the file.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If files are marked with generic security zones (Mark of the Web), then security classification is provided, but the ability to differentiate between trusted and untrusted apps is lost

Engineering Contradiction:
Improvesecurity classificationVSAvoidapp identity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the generic security zone concept into app-specific security principals. Instead of a single generic zone marker, each app receives a unique security principal identifier that segments the security classification space, allowing differentiation between multiple trusted apps while maintaining individual app identity information in file metadata.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (file broker with alternate data streams) that mediates between the app identity and security classification. The file broker captures app identifiers and stores them in alternate data streams, acting as an intermediary that preserves app identity information while enabling security decisions based on that identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If desktop applications treat all modern apps as untrusted, then security is maintained, but interoperability and user experience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by enabling different trust levels for different apps. Desktop applications can examine the security principal identifier in file metadata and apply locally appropriate trust decisions for each specific app rather than a blanket untrusted policy, allowing trusted apps like Microsoft Word to interoperability while maintaining security against untrusted apps.

Inventive Principle:
Principle #3Local quality

3Loss of information

If file metadata is enhanced to store app identifiers, then provenance tracking is improved, but metadata complexity increases

Engineering Contradiction:
Improveprovenance informationVSAvoidmetadata structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent uses nested doll by embedding app identifier information within alternate data streams that are nested within the file metadata structure. The security principal identifier is nested within the file's metadata, which itself is nested within the file system structure, allowing provenance information to be stored without fundamentally altering the core file format.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10176331B2Enhanced metadata to authentically report the provenance of a file
Publication Date: 2019.01.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10176331B2 patent drawing
  • US10176331B2 patent drawing
  • US10176331B2 patent drawing

AI summary

Aspects of the technology described herein can provide enhanced metadata to authentically report the provenance of a file. An exemplary computing device may have a file broker to receive an indication from a first security principal to write a file to a file system. The file broker can use one file utility to write the file, but use another file utility to write an identification of the first security principal and its opinion about the file into metadata associated with the file. Subsequently, the identification of the first security principal and its opinion may be used to authentically report the provenance of the file and applied in other security applications.